CVE-2026-32853 is a heap out-of-bounds read vulnerability affecting LibVNCServer versions 0.9.15 and prior, specifically within the UltraZip encoding handler. This flaw allows a malicious VNC server to exploit improper bounds checking in the HandleUltraZipBPP() function, targeting clients using the affected libvncserver_project library. Rated 8.1 HIGH (CVSSv3.1), exploitation requires user interaction but can be performed remotely with low attack complexity, potentially leading to information disclosure or application crashes. There is currently no evidence of active exploitation, nor are public exploit modules or significant community discussion available. Organizations should update to a fixed version (commit 009008e or later) to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.15CPE matchmatch criteria | cpe:2.3:a:libvncserver_project:libvncserver:*:*:*:*:*:*:*:* | ||
>= 0, <= 0.9.15CPE match | cpe:2.3:a:libvnc_project:libvncserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.